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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11* 


SECURITY COMMITTEE 


(Effective 23 August 1974) 


In. support of the DCI’s statutory responsibilities and of his efforts to 
improve the Intelligence Community’s product and to achieve more effi- 
cient use of intelligence resources, the community’s security policies and 
procedures must be effective and consistent for the protection of intelli- 
gence and of intelligence sources and methods,? and must ensure time- 
liness and economy in the handling of compartmented information. 
Therefore, pursuant to provisions of Subsection 102 (d) of the National 
Security Act of 1947, as amended, to provisions of NSCID 1 and to para- 
graph 2.b of NSAM 317, a new standing Committee of the USIB is hereby 
established. 


1. Name of the Committee 
The committee will be known as the Security Committee. 


2. Mission 


The mission of the committee is to provide the means by which the 
Director of Central Intelligence, with the advice of United States In- 
telligence Board principals, can: 


a. Ensure establishment of security policies and procedures includ- 
ing recommendations for legislation for the protection of intelligence 
and intelligence sources and methods from unauthorized disclosure. 


b. Review and formulate personnel, physical and document security 
policies, standards and practices and dissemination procedures applica- 
ble to all government departments and agencies as such policies, stand- 
ards, practices and procedures relate to the protection of intelligence 


*Supersedes DCID 1/11, effective 23 April 1965 and DCID 1/12 effective 23 
December 1964. 

2The term intelligence as used in this document applies only to information 
covered by statute, Executive Order, or other authority consonant with the DCI’s 
statutory responsibility for foreign intelligence and for the protection of intelli- 
gence and intelligence sources and methods from unauthorized disclosure. 
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sources and methods in consideration of the effectiveness, risks and 
cost factors involved. 


c. Review and formulate policies and procedures governing the re- 
lease of intelligence to foreign governments and international organiza- 
tions and the review of classified intelligence proposed for release to ; 
the public through declassification or other action. With respect to 
foreign disclosure, ensure that releases are in consonance with U.S. 
security policy. and that 95xX4 
the intelligence itself is accorded a degree of protection equal to that 
afforded by the United States. With respect to public release, ensure 
that disclosure or declassification actions are taken pursuant to proper 
authority and that they are accomplished so as to minimize the risk 
to other intelligence sources and methods. 


d. Ensure that appropriate investigations are made of any unauthor- 
ized disclosure or compromise of intelligence or of intelligence sources 
and methods and that the results of such investigations, along with 
appropriate recommendations, are provided to the Director of Central 
Intelligence. 


€ 25X1 


f. Review special security and compartmentation procedures and 
develop proposals for any necessary changes to achieve optimum use 
of intelligence consistent with protection of sensitive intelligence 
sources and methods. 


g. Ensure the development, review and maintenance of security 
standards and procedures for the protection of intelligence stored in or 
- processed by computers. 


3. Functions 


The functions of the committee are: 


a. To advise and assist the Director of Central Intelligence as appro- 
priate in the development and review of security policies, standards, 
procedures and practices for the protection of intelligence and intelli- 
gence sources and methods from unauthorized disclosures. 


b. To review, formulate and recommend to the Director of Central 
Intelligence policies, standards and procedures for the dissemination 
of intelligence materials, for the release of such materials to foreign 
governments, and for the review of classified intelligence proposed for 
use in unclassified activities. 


c. On behalf of the Director of Central Intelligence, to call upon 
departments and agencies to investigate any unauthorized disclosure 
or compromise of intelligence or of intelligence sources and methods 
occurring within their departments and agencies; to report the results 
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of these investigations to the Director of Central Intelligence, through 
the United States Intelligence Board. Such reports will (1) assess the 
disclosure’s impact on the U.S. intelligence process, and its implications 
for national security and foreign relations, (2) describe corrective 
measures taken or needed to prevent such disclosures in the future or 
to minimize the adverse effects of the case at hand, and (3) recommend 
any appropriate additional actions. 


d. The functions of the committee as they relate t 
computer security and special security com- 


partmentation are set forth in attachments 1, 2, and 3. 


Community Responsibilities 


a. Upon request of the committee chairman, USIB departments and 
agencies shall furnish to the committee within established security 
safeguards particular information needed by the committee and perti- 
nent to its functions. Temporary material and ad hoc personnel sup- 
port will be provided to the committee as needed and as mutually 
agreed upon by the departments and agencies represented on the com- 
mittee. 


b. Each USIB principal is responsible for investigation of any unau- 
thorized disclosure or compromise of intelligence or intelligence sources 
and methods occurring within his department or agency. When investi- 
gation determines that the possibility of compromise cannot be dis- 
counted, and the interests of the USIB or another USIB principal are 
involved or affected, the results of investigation will be forwarded to 
the Security Committee for review and possible remedial action as de- 
termined appropriate by the committee. 


Composition and Organization 


a. The committee will consist of a full-time chairman designated by 
the DCI, representatives of the chiefs of departments and agencies who 
are members of the USIB, and the representatives of the Departments 
of the Army, Navy, and Air Force. The chairman may invite a repre- 
sentative of the chief of any other department or agency having func- 
tions related to matters being considered by the committee to sit with 
the committee whenever matters within the purview of that depart- 
ment or agency are to be discussed. 


ubcommittees 
as needed and as approved by the DCI and by ad hoc working groups 
as approved by the chairman. The chairman of subcommittees will be 
designated by the committee chairman with the concurrence of the 
DCI. Membership on the subcommittees and ad hoc working groups 
need not be limited to member agencies of the committee, but may be 
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extended by the chairman to representatives of other departments and 
agencies having related functional responsibilities or support capabili- 
ties. 


c. The committee will have a full-time support staff to be provided 
by USIB departments and agencies as arranged and approved by the . 
DCI. 


for) 


. Rules of Procedure 


a. The committee shall meet upon the call of the chairman or at the 
request of any of its members. Items may be placed on the agenda by 
the DCI or by the chairman or any member of the committee. 


b. Decisions or recommendations will be formulated by the chairman 
after giving consideration to the views of the members. At the request 
of a dissenting member, the chairman will refer the decision or rec- 
ommendation along with dissenting opinion or opinions to the DCI. 


W. E. Colby 
Director of Central Intelligence 


25X1 


Approved For Release 911 RO00500010001-6 


25X1 Approved For Release 2005/08/08 : CIA-RDP82M00591R000500010001-6 


Next 1 Page(s) In Document Exempt 


Approved For Release 2005/08/08 : CIA-RDP82M00591R000500010001-6 


Approved For Rglease 2005/08/08 : CIA-RDP82M005948800500010001-6 
SECRET 


DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 
(Attachment 2) 


Computer Security 


The functions of the Security Committee include: 


(1) To review, formulate and recommend to the DCI policies, 
standards, and procedures to protect intelligence data stored or 
processed by computer. 


(2) To advise and assist the DCI, the Intelligence Community 
Staff, Committees of the United States Intelligence Board, USIB 
member agencies and departments, and other intelligence users 
with respect to all computer security issues and to resolve conflicts 
that may arise in connection therewith. 


(3) To formulate and recommend to the DCI resource pro- 
gramming objectives for USIB departments and agencies in the 
field of computer security in consideration of current and foreseen 
vulnerabilities and threats and with regard for the effective and 
efficient use of resources; to foster and to monitor an aggressive 
program of computer security research and development in the 
Intelligence Community in order to avoid unwarranted duplication 
and to assure the pursuit of an effective effort at resolving techni- 
cal problems associated with the protection of computer operations. 

(4) To coordinate all aspects of Intelligence Community efforts 
in defense against hostile penetration of Community computer 
systems as feasible to support other Government and national 
efforts aimed at improving computer security technology; to foster 
a coordinated program of Intelligence Community computer se- 
curity training and indoctrination. 

(5) To facilitate within the Intelligence Community the ex- 
change of information relating to computer security threats, vul- 
nerabilities, and countermeasures by providing a focal point for the 
evaluation of foreign intentions and capabilities to exploit Com- 
munity computer operations, for central notification of hostile 
exploitation attempts, for the preparation of damage assessments 
of incidents of foreign exploitation of intelligence computer opera- 
tions, and for the formulation of Community policy on the release 
of computer security information to foreign governments and in- 
ternational organizations. 
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(6) To review, formulate and recommend minimum computer 
security standards, procedures and criteria as guidance for system 
design, evaluation and certification of acceptable levels of security 
for computer systems. 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 
(Attachment 3) 


Compartmentation * 


The functions of the Security Committee as they relate to compartmenta- 
tion controls are: ? 


. . A. To. develop and recommend to the DCI, with the advice of 
the United States Intelligence Board, technical guidance for the estab- 
lishment, maintenance and improvement of coordinated compartmenta- 
tion systems. 
(1) Providing special protection to sensitive intelligence, in- 
- telligence information and intelligence sources and methods under 
the authority of Section 9 of Executive Order 11652. 


(2) Ensuring the establishment and disestablishment of com- 
partmentation of intelligence and intelligence information on the 
instructions of the DCI. 


(3) Ensuring coherent control by the DCI of the processes 
for access approvals to compartmented intelligence and intelli- 
gence information and of the processes for dissemination, sanitiza- 
tion or release of such intelligence information. 


(4) Ensuring the establishment and promulgation or appro- 
priate criteria for security and need-to-know access approvals. 
B. To formulate, coordinate, maintain and promulgate technical 


guidance for use in the administration of compartmentation controls 
at all echelons of department and agenc 


concerning: 
(1) Access approval criteria 


. aan Security. 


+The term “compartmentation” as used in this directive refers to the system 
whereby special Intelligence Community controls indicating restricted handling 
within collection programs and their end products are applied to certain types 
of intelligence information and material. The term does not include Restricted 
Data as defined in Section 11, Atomic Energy Act of 1954, as amended. 
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(3) Document identification, handling, accountability and 


destruction. 
(4) Automatic data processing and associated materials. 


C. To furnish technical guidance and assistance 


ication and decontrol responsibilities. 


D. To review and survey, when appropriate, with the cooperation 
and assistance of the USIB Principal concerned, the security standards, 
practices and procedures employed by USIB departments and agencies 

in relation to approved compartmentation policies, 
procedures and controls; and to make recommendations for practical 
improvements to the USIB Principals concerned through the DCI. 


TTT] 
Se 


F. To recommend security policies, in coordination with appropriate 
USIB committees, governing the release or disclosure of compartmented 
intelligence 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. ut i 


- SECURITY COMMITEE os - ee 
- (Ritective 23 August 1974) 


Jn support of the DCs statutory responsibilities 2 andeat his efforts ta - 
improve the Intelligence Cormmuunity’s product and to achieve more eft- 
cient use of intelligence resources, the community’s security policies and 
procedures must be effective aad consistent for the protection, of intel) . 


“gence and of intelligence sources and methods? and must ensuxe thme- 


liness and economy in the handling of compartraerted Information, — 
Therefore, pursuant to provisions of Subsection 102 (d) of the National 
Security Act of 1947, as amended, to provisions of NSCID 1 and ta para 

graph 2.b of NSAM 31%, anew fl asae Comunittee of ee Us 3B is ae ed 
este blisted. Re ee 


1. Name of the Bécimieivs 
. The committee will be known as the Seguely Committee. 


2, Mission 


The raission of the comunittee is to provide the wneans py which ‘ie 
Director of Central Intelligence, with the advice of United. Btates Ate 
telligence Board principals, can: . ; 


a. Ensure establishment of security policies and ee jyiciud~ 
ing recommendations for legislation for the protection of intelligence 
and intelligence sources and methods frora unauthorized disclosure, — 


b. Review and formulate personnel, phiysical and document security 
policies, standards and practices and dissemination procedures applica~ 
ble to all governrnent departments and agencies as such policies, stand. 
ards, pr actices and procedures relate to the protection ce intellig GEES 


* Supersedes DCM I/11, effective 23 April 1965 and DCD we cfteetive oe 
December 1934. 
' she term intelligence as tsed In this document appliles only to Information 
covered by statute, Executive Order, or other authority consonant with the DCT’s 
statutory responsibility for forelgn intelligence and for the protection of inteli~ 
gence and intelligence sources and methods from unauthorized disclosure. _ 
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Sources and methods in consideration of the effectiveness, risks and 
cost factors involved. 


c. Review and formulate policies and siicaaiiaes governing the re- 

. lease of intelligence to foreign governments and international organiza. 

tions and the review of classified intelligence proposed for release to’ 
the public through declassification or other action. With respect to 

foreign disclosure, ensure that releases are in consonance with U.S, | 
security policy, / » and that 
the intelligence itself is accorded a degree of pronoun equal to thak 

afforded by the United States. With respect to public release, ensure 


| that disclosure or declassification actions are taken pursuant to proper . : 


authority end that they are accomplished so ag to minixsize ane risks” 
to other intelligence sources and rnethods, ; 


d. Ensure that appropriate investigations are made of ax ¥ unautiore 


- Jzed disclosure or compromise of intelligence or of intelligence sources - - 


.: and methods and that the results of such investigations, along with 
- appropriate recommendations, are provided to the Director of Centrak | 
Intelligence, . ae Pee Fiat ek: 


e. | 


. 


f. Review special security and compartmentation procedures and 
-- develop proposals for any necessary changes to achieve optimum use _ 
of intelligence consistent with porsche of sensitive intelligence. . 
sources and methads. 2 
g. Ensure the development, review and rnatutenance of securl ty 
standards and procedures for the protection of intelligence stored bn or: 
- processed by computers, 7 


3. Funetions 


‘The functions of the committees are: 2 ge 
a. To adyise and assist the Director of Central intelligence as as appro 


7 a ve 


-ptiate in the development and review of security policies, standards, -. 


procedures and practices for the protection ‘of intelligence and intelli. ° 
gence sources and metheds from unauthorized. disclosures. i Pe : 

b. To review, formulate and recommend ta the Director of Centrak 
Intelligence policies, standards and procedures for the dissemination - 
of intelligence materials, for the release of such materials to foreign © 
govermments, and for the review of classified puget ce proposet fox 
use in unclassified activities. 


c. On behalf of the Director of Central Intelligence, to call upon 
departments and agencies to investigate any unauthorized disclosure 
or compromise of intelligence or of intelligence sources and methods 
occurring within their departments and agencies; to report the regults . 


cy 
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of these investigations to the Director of Central Tatelligence, through, 
the United States Intelligence Board, Such reports wilt (1). assess the 
disclosure’s impact on the U.S. intelligence process, andits implications 
for national security and foreign relations, (2) deseribe corrective’ 
measures taken or needed to prevent such disclosures in. the future or 
to minimize the adverse effects of the case at hand, and (3) yv:ecoramend 
any appropriate additional actions, ; 


da. The functions of the committee as they relate to. 
a: , computer security and special PCE, cor 
partmentation are set forth in attachmonts 1, 2, and 3 3, Foi sas 


4, Community Responsibilities 


a. Upon request of the committee chairman, USIB 6 coax inents end 
agencies shall furnish to the committee within established se curlhy 
safeguards particular information needed by the coramititee and nersi- 
nent to its functions. Temporary material and ad hoc personnel supe | 
port will be provided to the committee as needed and as mutually 
agreed upon by the departments and agencies represented on. the core 
mittee. ; 2 

b. Fach USES principal is responsible for investigation. of any unsu- 
thorized disclosure or compromise of intelligence or intelligence sources 
and methods occurring within his department or agency. Wher ixvestt- 
gation determines that the possibility of corapromise cannot be dis- 
counted, and the interests of the USIB or another USIG principal are 
involved or affected, the results of investigation will be forwarded toa 
the Security Cormmittee for review and possible remedial action as de- 
termined appropriate by the committee. 


5. Composition and Organization 


a. The committee will consist of a full-time chairman designated hy 
the DCI, representatives of the chiefs of departments and agencies wha 
are members of the USIB, and the representatives of the Departments 
of the Army, Navy, and Air Force. The chairman may invite a repre~ 
sentative of the chief of any other department or agency having func- 
-tions related to matters being considered by the coromittes to sit with 
the committee whenever matters within the purview of that depart. 
ment or agency are to be discussed. 


b. The coramittee will be supported by: 


subcommittees 
as needed and as approved by the DCI and by ad hoe working groups. 
as approved. by the chairman. The chairman of subcommittees will be 
designated by the committee chairman with the concurrence of the 
DCI. Membership on the subcommittees and ad hoc working groups 
need not be limited to member agencies of the commitiea, but may be 
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extended by the chairman to representatives of other departments and, 
agencies having related functional responsibilities or support capabili- 
. ties. : ee cr 
c. The coramittee will have a full-time support staff to be provided. 
by USIB departments and agencies as arranged and approved. by the 
DCL ae. ed oath. 


6. Rules of Procedure 


a, The comrnittee shall meet wpon the call of the chainman or at the 
request of any of its members. Items may be placed on the agenda hy 
the DCI or by the chairman or any member of the committee. ~~ 


b. Decisions or recoramendations will be formulated by the chairman 
after giving consideration to the views of the members, At the request 
of a dissenting member, the chairman will refer the decision or rece 
ommendation along with dissenting opinion or opinions to the DCL 
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WW. E, Coly Ey 
Director of Central Intelligence 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 
(Atiachment 2) | 


Computer Security 


The functions of the Security Committee include: 


(1) To review, formulate and recommend to the DCI -policies, 
standards, and procedures to protect intelligence data stored or 
processed by computer. 


(2) To advise and assist the DCI, the Intelligence Comraunity 
Staff, Committees of the United States Intelligence Board, USIB 
member agencies and departments, and other intelligence users 
with respect to all computer security issues and to resolve conflicts 
that may arise in connection therewith. 


(3). To formulate and recommend to the DCI. resource pro-. 

gramming objectives for USIB departments and agencies in the 

. field of computer security in consideration of current and foreseen 

vulnerabilities and threats and with regard for the effective and 
efficient use. of resonrces; to foster and to monitor an aggressive | 

program of computer security research and development in the 

Intelligence Community in order to avoid unwarranted duplication 

and to assure the pursuit of an effective effort at resolving techni- 

- cal problems associated with the protection of computer operations, 

. (4) Tocoordinate all aspects of Intelligence Community efforts 

in defense against hostile penetration of Community computer 

systems as feasible to support other Government and national 

efforts aimed at improving computer security technology; to foster 

a coordinated program of Intelligence Community computer se- 

curity training and indoctrination. 

(5) To facilitate within the Intelligence Community the ex- 
change of information relating to computer security threats, vul- 
nerabilities, and countermeasures by providing a focal point for the 
evaluation of foreign intentions and capabilities to exploit Com- 
munity computer operations, for central notification of hostile 
exploitation attempts, for the preparation of damage assessments 
of incidents of foreign exploitation of intelligence compu-er opera- 
tions, and for the formulation of Community policy on the release 
of computer security information to foreign governments and in- 
ternational organizations. 
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(6) To review, formulate and recommend minimum computer 
security standards, procedures and criteria as guidance for system 
design, evaluation and certification of acceptable levels of security 

_ for computer systems. 
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Compurtmentation® 


The taeicticns of the 2 Security Coimnittee as they relat te to compatineatn _ 
tion controls are:?  .- =, ie sip thee 24 wag tes PAD vos : 


‘A. To develop and Seed to the pet, With’ the "advice Of. 


the. United States Intelligence Board, technical guidance for the estas ~ 


lishment, maintenance and seas = oe ee 
tion systems. °. - °° : ae 


(1) Providing ne protection to enauee sai aliiente: ie oe ; 


telligence’ ‘information and intelligerce sources and ODS is under 


partme erase of intelligence and intelligence information. or the 
justructions of the DCL : 


(3) Ensuring coherent control by the DCT of the processes” 


for necess approvals to compartmented intelligence and intelli- 


_ gence information and of the processes for dissextination, sepitiza. — 


tion or release of such intelligence inforraation, 


(4) Ensuring the establishment and promulgation OX AYPrOs | 


ylate criteria for security and nee ed-bo-know access approvals. 
pp 


+B. Yo formulate, coordinate, maintain and promulgate technical 
puidance for use in the administration of compartment ation controls - 


- aball echelons of department 2 andagency _ oo a jactivity, % 
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. @) Access ee criteria| 
| 


. Physical sabe die, 


Ivhe term “compartmeatation” as used in this direetiva refers to ‘the system, 
whereby special Intelligence Community controls indicating vestriated handilne 
within collection programs and thelr end products are applied te Carteim types 
of Intelligence Informat ton and material ‘Che term does nob incluce Re tstoted 
Pata as defined in Section 11, Atomic Energy Act of 1054, azermendad 
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_ G. To furnish technical guidance and assistance | 
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jin connection with their sanitization, downgrading, declassi~ See 
fication and decontrol responsibilities, bugis 


- —, "To review and survey, when appropriate, with the cooperation 
and assistance of the USLB Pringinal concermed, the security standards, - 


jin relation to approved compartmentation policies, —.- 
procedures end controls; and to make recommendations for practical . 
improvernents to the USIa Principals concerted through the DCL 
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F. 'To recommend security policies, in coordination with appropriate _ 
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